5 Tips To Use Email Safely
Email is a quick and effective way to communicate. It’s also used by cybercriminals to trick people into giving away sensitive information. Here are some tips to use email safely.
Tip #1: Keep your work and personal email separate.
More than 3.2 billion logins, including Carilion email addresses, were leaked in recent years from websites including Netflix, LinkedIn, Bitcoin and others. There is an increased risk to the organization when employees link their work email to personal accounts. Examples are:
- Account hijacking: When sites such as LinkedIn, Gmail and Netflix get hacked and your work email is associated with those accounts, cybercriminals have a better chance of hacking your work email as well.
- Phishing attacks: If hackers learn your work email address, they have an easier time sending specific phishing emails to trick you into giving them information.
Only use your Carilion email address for work-related communications. Do not use your personal email account for Carilion business, and never auto-forward your Carilion emails to a personal account.
Tip #2: Strengthen your passwords.
Hackers will go to great lengths to figure out your password, and passwords that use seasons or dates are easily guessed (example: winter2022). In December, we moved to passphrases for our AD accounts (used for Carilion email, Epic and other Carilion apps).
You should create a unique password for each website you use. If you use the same password across multiple websites, a hacker who gets your credentials can compromise multiple accounts.To make your password stronger:
- Make it longer. Consider a passphrase of words that’s meaningful to you. Example: “Carvin’s Cove is beautiful!”
- Consider putting a special character in the beginning or middle of the password, not at the end. Example: “Carvin’s Cove = beautiful.”
- Avoid repeating numbers or letters.
Tip #3: Know when email is the right—or wrong—method of communication.
Are you writing something to a patient? MyChart is a secure platform and makes communications part of the patient’s medical record.
Do you need to communicate something that is sensitive? A face-to-face discussion may be one option to consider.
Are you sending a large volume of confidential information? Contact office_of_information_security@carilionclinic.org to discuss alternative, secure solutions.
Email messages containing confidential information should include the minimum amount of information necessary to accomplish the task and should only be distributed to those with a legitimate need to know.
Tip #4: Know when to send encrypted emails.
If you are sending an email to another Carilion employee at their Carilion email address, you don’t need to encrypt your email. Carilion-to-Carilion emails are private and secure.
If you are sending a message to someone at a non-Carilion email address, it will be automatically scanned for confidential information (Social Security numbers, patient and employee identifiers, payment information, health condition information, etc.). If any confidential information is included in the email, it will be encrypted by our software before leaving our network.
Type the word “SECURE” in the subject line of the email as an added level of protection when you are sending confidential information in the email or in an attachment.
Tip #5: Know where to go when you have questions.
Our email policy has more details and guidelines about using email. You can find it on PageCenterX.
If you have questions, contact our Information Security team at office_of_information_security@carilionclinic.org.
Email can be used by cybercriminals to trick you into giving away sensitive information.
Use your email safely with these tips.